Legal
GDPR Compliance
For schools and families in the European Economic Area and the United Kingdom, this page explains how we meet our obligations under the GDPR and UK GDPR, and how to exercise your rights.
Last updated · 13 August 2026
1. Controller and processor roles
When a family buys a plan directly, Sumeru Edutech Pvt Ltd is the controller. When we deliver a product to a school, the school is the controller and we act as its processor, under a data processing agreement signed before any pilot begins.
2. Lawful bases
- Contract — to provide the service you or your school signed up for.
- Consent — for optional analytics, and for any processing we ask you to opt into.
- Legitimate interests — to secure the service and prevent abuse, balanced against the rights of the learner.
- Legal obligation — for tax, accounting and lawful requests.
3. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Our products do not make such decisions: AI output is study material, and grading or progression decisions remain with teachers.
To exercise a right, email support@schoolexl.com with the account email. We respond within one month and may ask for proof of identity — or, for a learner’s data, proof that you are the parent, guardian or school.
4. International transfers
EU and UK customers can choose an in-region or Singapore data location. Where data reaches our teams outside the EEA/UK, transfers rely on the European Commission’s standard contractual clauses, the UK Addendum where applicable, and a transfer risk assessment.
5. Sub-processors
We use a limited set of sub-processors for hosting, payments, email and analytics, each bound by contract to GDPR-equivalent obligations. The current list is provided with the data processing agreement, and controllers are notified before a sub-processor is added so they can object.
6. Children
Accounts are opened by an adult, and consent for a child’s use is given by a parent, guardian or the school as controller. We apply data minimisation to learner records and do not profile children for advertising.
7. Breach notification
As a processor we notify the controller without undue delay after becoming aware of a personal data breach. As a controller we notify the supervisory authority within 72 hours where the breach is notifiable, and affected individuals where the risk is high.
8. Complaints
If you believe we have handled your data unlawfully, contact us first at support@schoolexl.com. You also have the right to complain to your local supervisory authority, or to the Information Commissioner’s Office in the United Kingdom.
Questions about this policy?
Write to support@schoolexl.com or use the contact form. We reply within one business day.